CVE-2026-62824
Remote Desktop Client Remote Code Execution Vulnerability
Description
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowThis is a serious Windows Remote Desktop client bug that can let a remote attacker run code if they can reach your machine and get you to connect to a specially crafted Remote Desktop session; most small businesses should treat it as urgent and patch.
CVE-2026-62824 is a stack-based buffer overflow (CWE-121) in the Windows Remote Desktop Client that can enable remote code execution over the network when an attacker sends a specially crafted Remote Desktop session/stream that reaches and is processed by the client.
What to do now
- Check your Windows version/build number for Windows 10, Windows Server 2012/2012 R2, or Windows Server 2016, and note the OS build.
- If your build is below the fixed versions listed below, install the vendor security update from Microsoft Update Guide for CVE-2026-62824.
- After updating, re-check the build number to confirm it matches or exceeds:
- Windows 10: 10.0.14393.9418
- Windows Server 2016: 10.0.14393.9418
- Windows Server 2012: 6.2.9200.26280
- Windows Server 2012 R2: 6.3.9600.23338
- If you can’t patch immediately, restrict Remote Desktop access at the network level (allow only necessary sources) and consider temporarily disabling Remote Desktop features for endpoints until patched.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62824 and every CVE in our database. Create a free account — no credit card required.
Create Free Account